CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,971 vulnerabilities with CWE-89
CVE-2008-2692
Joomla com_yvcomment <= 1.16.0 - SQL Injection via ArticleID Parameter
CVE-2008-2697
Joomla com_rapidrecipe 1.6.6-1.6.7 - SQL Injection via recipe_id Parameter
CVE-2008-2700
Galatolo WebManager 1.0 - SQL Injection via view.php id Parameter
CVE-2008-2701
Joomla com_gameq <= 4.0 - SQL Injection via category_id Parameter
CVE-2008-2688
pilot_cart 7.3 - SQL Injection via Article Parameter
CVE-2008-2673
powie pNews 2.08 and 2.10 - SQL Injection via shownews Parameter
CVE-2008-2676
iJoomla News Portal (com_news_portal) < 1.0 - SQL Injection via Itemid Parameter
CVE-2008-2678
Telephone Directory 2008 - SQL Injection via code or id Parameter
CVE-2008-2679
Realm CMS < 2.3 - SQL Injection via KeyWordsList kwrd Parameter
CVE-2008-2685
battleblog < 1.25 - SQL Injection via Entry Parameter
CVE-2008-2669
yBlog 0.2.2.2 - SQL Injection via Search or User Parameters
CVE-2008-2670
Insanelysimple2 Isblog - SQL Injection
CVE-2008-2671
DCFM Blog 0.9.4 - SQL Injection via Comments id Parameter
CVE-2008-2642
OtomiGenX 2.2 - SQL Injection via User Name Parameter
CVE-2008-2643
Joomla com_biblestudy < 6.0.7b - SQL Injection via id Parameter
CVE-2008-2647
mebiblio 0.4.7 - SQL Injection via JID Parameter
CVE-2008-2651
Joomla! Bulletin Board (com_joobb) 0.5.9 - SQL Injection via Forum Parameter
CVE-2008-2652
SMEWeb 1.4b and 1.4f - SQL Injection via idp and category Parameters
CVE-2008-2626
battleblog <= 1.25 - SQL Injection via comment.asp Entry Parameter
CVE-2008-2627
Joomla com_idoblog <= b24 - SQL Injection via UserID Parameter
CVE-2008-2628
com_equotes 0.9.4 - SQL Injection via id Parameter
CVE-2008-2629
LifeType - SQL Injection via albumId Parameter
CVE-2008-2630
JooBlog (com_jb2) 0.1.1 - SQL Injection via CategoryID Parameter
CVE-2008-2632
Joomla com_acctexp 0.12.x and earlier - SQL Injection via Usage Parameter
CVE-2008-2633
Joomla com_joomradio 1.0 - SQL Injection via id Parameter
Details
Vulnerabilities 19,971
Exploit Likelihood High